Though MS says that BitLocker doesn't have back doors [1], I wonder how true this actually is...
[1] http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...
Though MS says that BitLocker doesn't have back doors [1], I wonder how true this actually is...
[1] http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...
They could just type any information in they wanted to, upload a picture, hit print, and the process would mail them a drivers license like everyone else.
Don't get me wrong: I understand and appreciate your point, but I honestly don't know how most of us using TrueCrypt (e.g. me) are any better off than those who use a proprietary solution. The only difference I can see is any backdoors in TrueCrypt or PGP must be better hidden.
And to be perfectly honest, I'd rather trust the FLOSS crowd who checked TrueCrypt and other more or less popular encryption tools probably hundreds, if not thousands of times than trust the development team of a company refusing to release the source of their software.
[1] Yes, I am kidding, but I hope you catch my drift.
http://www.h-online.com/newsticker/news/item/Debian-package-...
This bug was injected for two years: the damage has been done, with literally over a million of weak keys that pollute the internet. That said, I acknowledge, that the ssl system has (perhaps even more) serious weaknesses beyond the keys themselves. It should have been caught days after commit, and never should have made it into debian stable (and debian has a very slow, thorough release cycle). But telnetd comes to mind, etc. Perhaps only OpenBSD shows consistent true efforts in open source auditing.
I don't have the experience, knowledge, and time (+ effort) to review every source-code line and every theorem used by an encryption application ... to make sure it's not doing something it shouldn't.
And (chances are) you don't either.
So it's not about closed-source or open-source, but rather it's about trust.
And that's my point. How can I trust someone who's unwilling to show me the source of their software and denies me my basic freedoms?
What I am not saying is that Free Software should be blindly trusted - that would be stupid and reckless. What I am saying is that for security[1], proprietary software cannot and must not be trusted, under any circumstances. You cannot even verify what the program you are using does? It's not secure, full stop.
And again, it's a massive difference between hiding a backdoor in a binary blob as opposed to essentially trying to hide it in plain sight. It's possible, but highly unlikely to go unnoticed for a prolonged amount of time. And if it is found, it will probably be fixed pretty much instantly as per Linus' Law.
Finally, corporations and businesses are bound to law for the most part. If they are required (or ordered) to include a backdoor for the FBI or NSA, they will most likely have to oblige. Not so much for Free Software. You essentially cannot force such a backdoor since even if the original maintainers include it, the project will just be forked, and law enforcement - to put it bluntly - can't do shit against it.
[1] And arguably everywhere else, too, but I'd prefer to stay on topic.